Free Practice Questions for the Symantec Data Loss Prevention 250-587 Exam (2026 Updated)
At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Symantec 250-587 exam. To support your certification journey, we have made a selection of our premium 2026 Data Loss Prevention practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.
A DLP administrator has enabled and successfully tested custom attribute lookups for incident data based on the Active Directory LDAP plugin. The Chief Information Security Officer (CISO) has attempted to generate a User Risk Summary report, but the report is empty. The DLP administrator confirms the Cisco’s role has the “User Reporting” privilege enabled, but User Risk reporting is still not working.
What is the probable reason that the User Risk Summary report is blank?
Which two (2) actions are available for a “Network Prevent: Remove HTTP/HTTPS content” response rule when the content is unable to be removed? (Choose two.)
Which option correctly describes the two-tier installation type for Symantec DLP?
Which statement accurately describes where Optical Character Recognition (OCR) On-Premises DLP Core components must be installed?
A DLP administrator needs to stop the PacketCapture process on a detection server. Upon inspection of the Server Detail page, the administrator discovers that all processes are missing from the display.
What are the processes missing from the Server Detail page display?
What is required on the Enforce server to communicate with the Symantec DLP database?
A divisional executive requests a report of all incidents generated by a particular region, summarized by department.
What does the DLP administrator need to configure to generate this report?
Which server target uses the “Automated Incident Remediation Tracking” feature in Symantec DLP?
Where in the Enforce management console can a DLP administrator change the “UI.NO_SCAN.int” setting to disable the “Inspecting data” pop-up?
Which two automated response rules will be active in policies that include Exact Data Matching (EDM) detection rule? (Choose two.)
What is the correct order for data in motion when a customer has integrated their CloudSOC and DLP solutions?
A DLP administrator has performed a test deployment of the DLP 15.0 Endpoint agent and now wants to uninstall the agent. However, the administrator no longer remembers the uninstall password.
What should the administrator do to work around the password problem?
A DLP administrator has added several approved endpoint devices as exceptions to an Endpoint Prevent policy that blocks the transfer of sensitive data. However, data transfers to these devices are still being blocked.
What is the first action an administrator should take to enable data transfers to the approved endpoint devices?
The Symantec Data Loss risk reduction approach has six stages.
Drag and drop the six correct risk reduction stages in the proper order of Occurrence column.
Why would an administrator set the Similarity Threshold to s=zero when testing and tuning a Vector Machine Learning (VML) profile?
Which two factors are common sources of data leakage where the main actor is well-meaning insider? (Choose two.)
Which of the following is a good use case for Structured Data Identifiers (SDIs)?
An organization wants to restrict employees to copy files only a specific set of USB thumb drives owned by the organization.
Which detection method should the organization use to meet this requirement?
What should an administrator do if DLP policies are generating too many false positives?
Why would an administrator set the Similarity Threshold to zero when testing and tuning a Vector Machine Learning (VML) profile?
Where do you configure the list of Endpoint Servers (or load balancers) to which a DLP Agent can report?
Which statement accurately describes where Optical Character Recognition (OCR) components must be installed?
In the context of Network Discover scanning of Exchange servers, what is the Exchange Autodiscover service?
A DLP administrator created a new agent configuration for an Endpoint server. However, the endpoint agents fail to receive the new configuration.
What is one possible reason that the agent fails to receive the new configuration?
Which two (2) detection technology options run ONLY on detection servers and NOT on endpoint agents? (Choose two.)

